Haystack
← Back to Jobs
Technology
IS

IAM Security Engineer(Wireless)(NAC/MFA)

iCUBE SolutionsUnited States🇺🇸United StatesPosted 25 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
United States
Posted
22 hours ago
MFAOAuthSAMLAzure

Job Description

IAM Security Engineer(Wireless)(NAC/MFA)

Remote

6 Months Contract

Job Description:

We are seeking a Wireless & Identity Security Engineer to design, build, and deploy a secure wireless onboarding solution that integrates enterprise Wi-Fi authentication with Microsoft Entra ID (Azure AD) and enforces multi-factor authentication (MFA) at the network edge. This role blends wireless infrastructure engineering Cisco Catalyst Center + ISE) with identity federation engineering (SAML/OAuth, Conditional Access policy design). The successful candidates will be equally comfortable configuring RF/AP hardware in the field and building identity provider integrations in a lab.

Key Responsibilities

  • Design and build the captive portal / splash page authentication flow, integrating with Microsoft Entra ID as the identity provider (SAML or OAuth/OIDC).
  • Configure Conditional Access policies in Entra ID to enforce MFA push notification on wireless sign-on.
  • Reconfigure existing wireless infrastructure at the Herndon, VA site (Cisco C9130AXI-B APs) to support the new authentication flow.
  • Plan and execute a greenfield wireless deployment at the Maryland site, including RF design and installation of 8 new access points.
  • Build and validate NAC policies (if ISE path is chosen), including device profiling, guest/BYOD carve-outs, and failover/fallback authentication scenarios.
  • Conduct pilot testing with a small user group prior to full rollout; troubleshoot edge cases (non-domain devices, personal phones, shared workstations).
  • Document high-level design (HLD), low-level design (LLD), and standard operating procedures for ongoing support.
  • Provide hypercare support post-deployment, including monitoring, tuning, and knowledge transfer to the client's internal IT/network team.
  • Coordinate site logistics and installation windows with client stakeholders and the project manager.

Required Qualifications

  • 5+ years of experience in enterprise wireless network engineering (Cisco Meraki and/or Cisco Catalyst/Aironet platforms).
  • Hands-on experience with Cisco ISE (policy sets, authentication/authorization policies, NAC)
  • Demonstrated experience integrating network authentication with a cloud identity provider Microsoft Entra ID / Azure AD strongly preferred.
  • Working knowledge of SAML, OAuth 2.0/OIDC, and Conditional Access policy configuration.
  • Experience designing and deploying MFA-enforced authentication flows (push-based, e.g., Microsoft Authenticator).
  • Practical RF design experience site survey, AP placement, channel/power planning for greenfield deployments.
  • Comfortable working independently on-site for physical AP installation and cabling coordination with facilities/electricians as needed.
  • Strong documentation skills (HLD/LLD, runbooks).
  • Ability to work within compliance-driven timelines (audit-driven deadlines, defined go-live dates).

Preferred Qualifications

  • Certifications: CCNP Enterprise/Security, Cisco ISE SISE, Meraki CMNA/CMNO, or Microsoft SC-300 (Identity and Access Administrator).
  • Prior experience supporting a defense/aerospace client environment (e.g., client supply chain compliance requirements).
  • Experience with a phased rollout methodology (Discovery ? Design ? Build ? Pilot ? Deploy ? Hypercare).
  • Familiarity with 802.1X, EAP-TLS/PEAP, and certificate-based authentication as a fallback design option.

Thanks,

Vinod.

Similar jobs